CVE-2017-0197 is a DLL loading vulnerability affecting Microsoft OneNote 2007 SP3 and 2010 SP2, allowing remote attackers to execute arbitrary code through crafted documents. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L), leading to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). While not listed in CISA's KEV catalog and lacking public exploit intelligence like Metasploit or ExploitDB modules, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:onenote:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:onenote:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.